CVE-2025-29087

LOW

SQLite 3.44.0-3.49.0 - Integer Overflow in concat_ws() SQL Function

Title source: llm
STIX 2.1

Description

In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.

Scores

CVSS v3 3.2
EPSS 0.0034
EPSS Percentile 25.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-190
Status published
Products (1)
sqlite/sqlite 3.44.0 - 3.49.1
Published Apr 07, 2025
Tracked Since Feb 18, 2026